Handling Billing Information using Java - Insecure??

Our firm is currently developing an e-commerce building site using java. An issue has propped up while trying to design how thw site should handle payments . The developers are adamant that due to the ease with which class files can be decompiled , we shouldnt let the user enter his payment info( like credit card no: ) on our site , rather forward to a secure gateway site. But the client is of the view that doing this will break the flow of the process and points out that many sites do make usre enter info on their site . I'm sure you must know more on this than i do , is it safe to let the user enter the info on our site and let we pass them to the provider ?

confused__ wrote:
Our firm is currently developing an e-commerce building site using java. An issue has propped up while trying to design how thw site should handle payments . The developers are adamant that due to the ease with which class files can be decompiled , we shouldnt let the user enter his payment info( like credit card no: ) on our site , Fire those developers and hire somebody competent.
Ther are plenty of secure sites that are backed by Java. You need to make sure that the information that needs to be secured is encrypted before transmission. You'd do this by using HTTPS rather than HTTP. This has nothing to do with what language you're using on the back end. If you're using an applet on the client side, it should still be possible to use HTTPS.
Typically in a web app like this, the Java is all on the server side, and the end user can never see it. Even if it is an applet, so the Java does come to the client browser, the CC info will not be inside the source code, and seeing the source will not give a bad guy the ability to intercept CC numbers, unless your developers are idiots and use a homegrown, non-keyed encryption algorithm whose security relies on not knowing the algorithm, or embed a database connection URL and password in the applet code.
Seriously--I would be very worried about your developers' qualifications.
Edited by: jverd on Jun 21, 2008 12:02 PM

Similar Messages

  • HT1918 How to delete billing information using iOS

    How do I delete billing information using iOS device

    you can't, you should use iTunes on a computer for this. log in, select 'account' and 'payment method/info'
    then you can select 'none' and save settings

  • How to get Remote System informations using java

    Hi
    Any one know how to get remote machine information, processor speed , mainmemory size, etc using java .
    Thanks in adv.......

    Hi
    Any one know how to get remote machine information,
    processor speed , mainmemory size, etc using java .
    Thanks in adv.......That's impossible.
    Kaj

  • How to get regional options information using java api

    Hi all
    I want to read what is properties like what is the currency symbol , what is the precession , what is the digit seperator and No of digits after the decimal .. such information i want to get using the java API
    How can i get this information.
    i tried with Locale API.
    But it always giving me the default information only.
    If i go and change those things in teh regional options it is not effecting
    Any suggestions.
    Thankin you

    http://java.sun.com/j2se/1.4.2/docs/api/java/text/DecimalFormatSymbols.html

  • Need an information using java.sql in jsp

    I found that there is a 'dataset' like architecture in .NET, is there any 'dataset' like substance in our java, if it is means can you give me some ideas for using it in jsp, give me some example for saving a record in the mysql database. very urgent please,

    KIRUPA_SHANKAR wrote:
    I found that there is a 'dataset' like architecture in .NET, is there any 'dataset' like substance in our java, if it is means can you give me some ideas for using it in jsp, give me some example for saving a record in the mysql database. Shouldn't be doing database stuff in JSPs. Use JSTL and its <sql> tags if you must.
    RowSet might be close. I don't write .NET.
    very urgent please,Not to me.
    %

  • Handling ttf file using java

    hi all,
    Is there is any Java API for editing ttf file?.
    I want add glyphs to unicode in the ttf file.

    Hi Prabhu,
    I would prefer developing scenario using File to File simple and better solution,i have transferred 50mb files using only ID design, i never experienced any problem at all.
    as prateek mentioned java proxy required additional support, even you need to create IR objects,that means the server utilization will be more,obviously it takes lot of resources compare to simple file to file.
    if you looking for generic solution , if you are good java developer then you can develop one reusable proxy program .
    i have developed some reusable generic java mapping programs relevent to my requirement,but in your case dont make complex file to file works perfectly.
    it is my suggestion.
    Regards,
    Raj

  • Why is my billing information not being review correctly...like it sayes my apple id has not yet been used in the itune store and it tells me to review my account info but for some reason it doesnt work

    why is my billing information not being review correctly...like it sayes my apple id has not yet been used in the itune store and it tells me to review my account info but for some reason it doesnt work

    Hi there ethangabe,
    You may find the information in the article below helpful.
    Using an existing Apple ID with the iTunes Store, Mac App Store, and iBooks Store
    http://support.apple.com/kb/ht2589
    -Griff W. 

  • HT1918 I have an Apple ID which I have not used at the iTunes store yet, but when I try to log in I am asked to review my account and when I click okay the billing information page comes up, however, I do not use a credit card and there is no option to ch

    I have an Apple ID and  a password, but when I try to sign in I am asked to review my account. When I click okay, it takes me to the billing information page and since I do not use or have a credit card anymore, I want to change the payment option, but there does not seem to be anyway to change this, as the only options available for payment are three different types of credit cards. How do I edit this information so I can pay by PayPal or have the payment option as none? I would like to be able to purchase music using a PayPal account. I have sent three emails to support and have not been able to fix this problem. Would appreciate any help on how I can change the payment information.

    I have just worked this out; see below
    https://discussions.apple.com/message/15404253#15404253

  • Is there any way to create another Apple ID while still using billing information and purchases from a previous one?

    We have 5 iDevices on one account and I cannot use features like iCloud without mixing information with the rest of my family. We've made due for years, but it's getting very tedious. I would love to have my own ID and password but still be able to be under my parents' billing information. (The more I think about it, the more I begin to doubt the liklihood of the possibility)
    At the very least, is there a way I can create a new ID and keep/transfer the purchases (and all other information like contacts, notes, etc.) I've made on the original account without starting over?

    For Family Sharing, why must I add a credit card to add a child? Please explain why my debit card, on file, isn't enough…
    Create an iTunes Store, App Store, or iBooks Store account without a credit card or other payment method - Apple Suppor…
    Family Sharing and Apple IDs for kids - Apple Support
    Set up and manage iTunes Allowance - Apple Support

  • How do I set my AppStore up using US Billing Information at a European AppStore?

    My husband is in the US military, and we are currently stationed in The Netherlands. We've both had iPhones (mine a 4s, his a 4) for just over a year, and we've NEVER had an issue like this. Yesterday, I went to update a few apps, and got a message that I couldn't do it because my account was hooked up to the US store, and that I needed to switch to a Dutch store. Fine. There is an option (if you set up your store on a computer) to use billing information from a country different from the store you're using. Excellent. Except it doesn't work. I spoke to three people at Apple Support and the best answer they could give me was to just get a Dutch credit card - not happening. I've hard reset the phone, tried using our Dutch bank information, and have tried our US billing info in the Dutch store, all to receive the same message. My questions: How can I set it up so that I can use my US billing information at the Dutch store? Why would my account be good to go for 15 months and decide to stop working yesterday? Is there a permanent fix or am I going to encounter this problem again?

    If you are in the Netherlands then you can only use their store (you need to be in a country to use its store), and if using a credit card then you can only use one issued by a Dutch bank - US credit cards can only be used in the US with US iTunes accounts.
    Are iTunes gift cards available in the Netherlands ? If they are then you can use those as your payment method.

  • HT5622 how can I skip the visa check or billing information step to use my apple ID, because I don't have a visa card?

    Dear All,
    I just bought the new Ipad mini, and I have a problem when I'm signing in on my apple id I just made,
    1) when I sign in it logs in but a pop window appear with this message: this apple id not yet used on apple store, then it give me 2 options cancel or review,
    I click on review it take me to a page for the agreement and conditions, I agree with it, it takes me to another page with the name of billing information which contins visa card or payment method verification that I can't skip because I don't have a visa card.
    could anyone tell me what to do?

    Create a NEW account using these instructions. Make sure you follow the instructions. Many do not and if you do not you will not get the None option. You must use an email address that you have not used with Apple before.
    Creating an iTunes Store, App Store, iBookstore, and Mac App Store account without a credit card

  • Used a prepaid credit card on my account, can no longer download free apps. Cannot remove from billing information.

    Firstly, if this is the wrong category, I apologize.
    I used a prepaid credit card on my apple account to purchase an app add on for $2. The credit card only had $2.50 on it, which is why I used it. Now that I spent what was on it, I am not able to download even free apps from the app store. I have tried signing out and back in to try and erase the data, didn't work. I tried to create a new Apple ID and for some reason the option to not have a credit card on your billing info is no longer there like it was when I made my original account. I also tried to go through iTunes on my PC to fix the issue, it didn't work. I don't have another credit card to put on my account as I always use pre-paids as needed. Does anyone know how to get this card off of my billing information so I can download the free apps again?!

    Hi there Brittney93,
    You may find the information in the article below helpful.
    iTunes Store: Changing your payment information
    http://support.apple.com/kb/ht1918
    Changing your payment information using a computer
    Open iTunes.
    Choose Store > Sign In.
    Enter your Apple ID and password and click Sign In.
    Choose Store > View Account.
    Enter your account password and click View Account.
    From the Apple Account Information page, click Edit to the right of Payment Type.
    Note: You can find the payment methods that the iTunes Store accepts in the Payment Type section. If you don't want a payment method on your account, select None in the Payment Type section.
    Click the Done button after you've updated all of your information.
    -Griff W. 

  • Becouse of expire of credit card I updated billing information by providing data of new credit card but system just says "We're sorry, the billing information on file could not be used for this payment. Please update your information.". What exactly is wr

    Becouse of expire of credit card I updated billing information by providing data of new credit card but system just says "We're sorry, the billing information on file could not be used for this payment. Please update your information.". What exactly is wrong?

    Are you 100% sure that every detail of your information is the same in each place?
    Make sure that EVERY DETAIL is the same in every place you enter your information
    -right down to how you spell and punctuate the parts of your name and address
    Change/Verify Account https://forums.adobe.com/thread/1465499 may help
    -Credit card https://helpx.adobe.com/utilities/credit-card.html

  • Geting this errror, eventhough information is ok: We're sorry, the billing information on file could not be used for this payment. Please update your information.

    Geting this errror, eventhough information is ok: We're sorry, the billing information on file could not be used for this payment. Please update your information.
    And please remove one of my unassigned user.

    Are you 100% sure that every detail of your information is the same in each place?
    Make sure that EVERY DETAIL is the same in every place you enter your information
    -right down to how you spell and punctuate the parts of your name and address
    Change/Verify Account https://forums.adobe.com/thread/1465499 may help
    -Credit card https://helpx.adobe.com/utilities/credit-card.html

  • Access mirror site using java, download files and other information?

    Hi, I have 2 nodes/servers on the system both running webservers and having the same interface, but at a time user will access one node at a time from their browser, but this interface will be able to allow the user to get information from the both the nodes. the information that the user can get is DB stored as well as files on the disk of either node.
    i can manage the DB, cuz there is nothing to it, but how do I get files from the other node?
    currently any files/web documents are all stored in a application directory of the web root and protected by htaccess i believe, so when a user logs on to node one he can access all plain text/binary files along with web content since the web server authorizes the user to access anything in that dir. but at the same time from the same session I want to be able to access files in a mirror site using the same username and password and not having him to enter it again. the username/pass combo is replicated on both the servers, it this possible?
    currently i use the http password protection provided by apache to access one node, but can i use the same session on another machine with the same credentials?
    If this is not possible how can i do this programatically using java? can i do can "ls" on the directory i want on another server and display the list to the user and then when he clicks on that file name i fetch it from the backup/mirror server and have him save it using http or ftp?
    It would be great if we can get a solution to this.
    Thank you very much in advance.
    Ankur

    If you install the web server on different machines, It is possible to share the informations between them.

Maybe you are looking for